]> git.koha-community.org Git - koha.git/commit
Bug 36244: Do template toolkit processing first
authorAndreas Jonsson <andreas.jonsson@kreablo.se>
Thu, 7 Mar 2024 09:12:25 +0000 (09:12 +0000)
committerWainui Witika-Park <wainuiwitikapark@catalyst.net.nz>
Wed, 27 Mar 2024 05:30:13 +0000 (05:30 +0000)
commitf6094bd90a3c81f8c9c30f45fab1b7c9a0e3f7e2
treee8219d59876d16e25de1214788444bd0760fbb88
parentbe99f17c78ccf2d6c387f373b9edc76e69cba429
Bug 36244: Do template toolkit processing first

To avoid injection of template toolkit code
from database fields that are controlled by
untrusted sources.

Test plan:

* review subtest 'Template toolkit syntax in
  parameters' in t/db_dependent/Letters.t
* Run the unit test:
  prove t/db_dependent/Letters.t

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
Signed-off-by: Wainui Witika-Park <wainuiwitikapark@catalyst.net.nz>
C4/Letters.pm